Headline
GHSA-xc4w-28g8-vqm5: Path Traversal in Gravitee API Management
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
Path Traversal in Gravitee API Management
Moderate severity GitHub Reviewed Published Aug 24, 2022 • Updated Aug 30, 2022
Related news
CVE-2019-25075: GitHub - gravitee-io/gravitee-api-management: Gravitee.io - OpenSource API Management
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.